安全

安全扫描与漏洞检测

显示 1465-1488 / 共 2332 个技能
quangrau

drill-recovery

quangrau

Disaster recovery drill exercises and security checklists for web application projects (SPA, SSR, full-stack web apps). Focused on solo/indie developers using free-tier infrastructure (Vercel, Supabase, Cloudflare, Netlify, Railway, etc.). Bridges big-tech best practices (NIST, Google SRE DiRT, ISO 22301) to indie scale. Use when the user mentions drills, disaster recovery, security audit, incident simulation, project health check, resilience testing, backup strategies, secret rotation, or incident response for web projects. Not for mobile apps, desktop software, CLI tools, or games.

代码生成 13 6个月前
yanko-belov

auth-patterns

yanko-belov

Use when implementing authentication. Use when storing passwords. Use when asked to store credentials insecurely.

认证鉴权 13 7个月前
Bikach

security-guardian

Bikach

Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.

API 开发 13 9个月前
xirothedev

nestjs-best-practices

xirothedev

NestJS best practices and patterns for building scalable, maintainable backend applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper architecture, security, performance, and code quality. Triggers on tasks involving NestJS modules, controllers, services, guards, pipes, middleware, Prisma database operations, authentication, or any NestJS-specific patterns.

数据库 12 7个月前
NextronSystems

thor-skills

NextronSystems

Entry point and router for THOR-related work: running scans, analyzing THOR logs, troubleshooting THOR behavior, maintaining THOR installs, THOR Lens workflows, writing THOR plugins (v11+), and creating custom signatures/IOCs.

代码评审 12 7个月前
scaleto

Comunicador Backend

scaleto

Enlace A2A del Grupo Backend. Gestiona la comunicación con otros grupos del Conglomerado.

Kubernetes 8 7个月前
scaleto

Comunicador Seguridad

scaleto

Enlace A2A del Grupo Seguridad.

MLOps 8 7个月前
scaleto

Comunicador Testing

scaleto

Enlace A2A del Grupo Testing.

安全 8 7个月前
scaleto

Orquestador Seguridad

scaleto

Líder del Grupo Seguridad. Planifica y delega tareas de ciberseguridad, auditorías, compliance y pentesting a los especialistas del grupo.

数据库 8 7个月前
scaleto

Comunicador DevOps

scaleto

Enlace A2A del Grupo DevOps.

缓存 8 7个月前
aashari

mail-security

aashari

Find security-related emails — login alerts, 2FA changes, password resets, new device notifications, suspicious activity, and account security events across all accounts. Use when user asks about security alerts in their email, account access notifications, or wants to review security events. Arguments: optional time range or account/service filter.

认证鉴权 5 6个月前
JDDoesDev

goodvibesonly

JDDoesDev

Security scanner for vibe-coded projects. AUTO-INVOKE this skill before any git commit, git push, or when user says "commit", "push", "ship it", "deploy", "is this safe?", "check for security issues", or "goodvibesonly". Also invoke after generating code that handles user input, authentication, database queries, or file operations.

数据库 5 7个月前
sam-fakhreddine

wfc-deepen

sam-fakhreddine

Augments an existing /wfc-plan directory by researching codebase patterns, project documentation, and dependency constraints to add supporting evidence to tasks. Reads TASKS.md and PROPERTIES.md, simulates parallel analysis across 4 dimensions, and appends sourced findings as annotations. Does NOT modify task structure, add/remove tasks, or write implementation steps. Triggers: /wfc-deepen, /wfc-deepen <path>, "add research evidence to the plan", "validate plan against codebase patterns", "annotate plan with known pitfalls", "cross-reference plan with existing solutions". Not for: writing or expanding task implementation steps; decomposing tasks into subtasks; prioritizing or reordering tasks; adding or removing tasks; pre-planning research before a plan directory exists; targeted research on specific questions unrelated to plan validation; re-deepening plans with existing Research Findings sections (use --force to override); general research with no plan context.

自动化 5 6个月前
richfrem

copilot-cli-agent

richfrem

Copilot CLI sub-agent system for persona-based analysis. Use when piping large contexts to GitHub Copilot models for security audits, architecture reviews, QA analysis, or any specialized analysis requiring a fresh model context.

智能体 5 6个月前
subhashdasyam

security-antipatterns-python

subhashdasyam

Use when generating Python code for web applications, APIs, or handling user input - prevents OWASP Top 10 vulnerabilities in Django, Flask, FastAPI

认证鉴权 5 7个月前
aashari

mail-digest

aashari

Email digest for any time period — today, yesterday, last N hours/days, this week, a specific date, or while-I-was-away ranges. Categorizes by urgency, surfaces unread, flags financial/security emails, filters noise. Auto-invoke when user asks about email for any time period: "what came in today", "catch me up", "any emails this week", "what did I miss", "emails from yesterday", "last 3 hours", "since Monday".

CLI 工具 5 6个月前
masayan1126

tech-blog-seo-draft-creator

masayan1126

テックブログ記事の下書きをSEO最適化込みで一括作成するスキル。雑なメモから体裁を整え、タイトル・メタディスクリプション・ハッシュタグまで生成。「SEO込みで記事にして」「SEO最適化された下書きを作成して」「公開できる形にして」などのリクエストで利用。

代码评审 5 6个月前
richfrem

audit-plugin

richfrem

Audits a local plugin directory to ensure it perfectly matches the Agent Skills and Claude Plugin Open Standards.

智能体 5 6个月前
clix-so

auditing-permission-ux

clix-so

Audits notification permission request flows. Use when reviewing or improving permission prompts, settings paths, or denial handling.

分析 5 7个月前
krishagel

seven-advisors

krishagel

Seven Advisors decision council - structured multi-perspective deliberation for important decisions. Use when facing complex choices, strategic decisions, or when you need to think through a problem from multiple angles.

代码评审 5 7个月前
sam-fakhreddine

wfc-security

sam-fakhreddine

Architectural threat modeling (STRIDE) and design-level security analysis for software systems. Analyzes system descriptions, architecture diagrams, or explicitly pasted configuration files. Does NOT perform live CVE scanning, code logic review, or implementation patching. Use when: User requests threat modeling, attack surface mapping, or static dependency risk assessment. Do NOT use when: User requests live vulnerability scanning, code review, specific bug remediation (SQLi, XSS), or compliance auditing.

代码评审 5 6个月前
ayushxx7

project-showcase

ayushxx7

"Automate the creation of high-quality project showcases, including UI captures using Playwright, professional README galleries, and feature summaries for portfolios or social media."

代码评审 5 4个月前
richfrem

audit-plugin-l5

richfrem

Triggers the L5 Red Team Sub-Agent to rigorously audit a plugin against the 39-point L4 pattern matrix.

智能体 5 6个月前
richfrem

red-team-review

richfrem

"(Industry standard: Review and Critique Pattern) Primary Use Case: Iterative generation paired with adversarial review, continuing until an 'Approved' verdict is reached. Orchestrated adversarial review loop. Use when: research, designs, architectures, or decisions need to be reviewed by red team agents (human, browser, or CLI). Iterates in rounds of research → bundle → review → feedback until approved."

学术 5 6个月前